Bug #74888 [NEW]: Timeout never or randomly reached for TLS sockets

From: Date: Sun, 09 Jul 2017 21:21:01 +0000
Subject: Bug #74888 [NEW]: Timeout never or randomly reached for TLS sockets
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209947@lists.php.net to get a copy of this message
From: mmn at hethane dot se Operating system: Ubuntu 16.04 PHP version: 7.2.0alpha3 Package: Streams related Bug Type: Bug Bug description:Timeout never or randomly reached for TLS sockets Description: ------------ Hello I am using the PEAR HTTP_Request2 library in the software GNU social to make remote requests. I have noticed recently a "malicious" remote server in our federated network that simply replies _extremely_ slowly_ it seems. This causes our background processes - which run in PHP - to stall whenever connecting to these remote servers. For this reason, PHP has the default_socket_timeout=60, which should cause connections to die relatively quickly (at least with double that specified timeout in seconds, according to bug #48280 at least). However, this does not seem to happen. The server in this case manages to keep alive connections with socket timeout of 2 seconds for much longer than that. I don't know if it is related to the timeout value - but it does _seem_ to be proportionate to the configured timeout (2 second timeouts die faster than 10 second timeouts etc.). With HTTP_Request2 this _only_ happens with the Socket adapter and not the Curl adapter (which flawlessly hits the timeout on the millisecond) which leads me to believe it's the underlying PHP sockets that have an issue here. I'm thinking it could be related to bug #41631 that seems to have been a long-living issue with TLS connections not respecting the socket timeout? This has so far only been experienced in HTTPS connections in GNU social at least. The below test script uses HTTP_Request2 as mentioned, https://pear.php.net/package/HTTP_Request2 (maybe requires some other PEAR stuff too) Test script: --------------- require('HTTP/Request2.php'); $r = new HTTP_Request2(); $r->setConfig(['connect_timeout'=>1, 'timeout'=>2]); $r->setMethod($r::METHOD_POST); foreach(['Thanks-For-Debugging: Really like it.'] as $header) { $r->setHeader($header); } $r->setUrl('https://hash.my/api/subscriptions/1234'); $time=time(); echo "$time\n"; try {$r->send();} catch(Exception $e){echo get_class($e).': '.$e->getMessage();} echo "\nIt actually took: ".(time()-$time)." seconds\n"; Expected result: ---------------- HTTP_Request2_MessageException: Request timed out after 2 second(s) It actually took: 2 seconds Actual result: -------------- HTTP_Request2_MessageException: Request timed out after 2 second(s) It actually took: 48 seconds (Note that the value where it says "after n second(s)" is just HTTP_Request2 reporting it like that because it was my configured, desired, value.) -- Edit bug report at https://bugs.php.net/bug.php?id=74888&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74888&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74888&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74888&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74888&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74888&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74888&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74888&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74888&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74888&r=support Expected behavior: https://bugs.php.net/fix.php?id=74888&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74888&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74888&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74888&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74888&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74888&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74888&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74888&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74888&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74888&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74888&r=mysqlcfg

« previous php.bugs (#209947) next »